Skip to content

DET0765 Detection of Service Stop

Item Value
ID DET0765
Version 1.0
Created 21 October 2025
Last Modified 21 October 2025

Technique Detected: T0881 (Service Stop)

Analytics

ICS

AN1897

Monitor for changes made to files that may stop or disable services on a system to render those services unavailable to legitimate users. Monitor executed commands and arguments that may stop or disable services on a system to render those services unavailable to legitimate users. Remote access tools with built-in features may interact directly with the Windows API to perform these functions outside of typical system utilities. For example, ChangeServiceConfigW may be used by an adversary to prevent services from starting. For added context on adversary procedures and background see Service Stop. Monitor processes and command-line arguments to see if critical processes are terminated or stop running. For added context on adversary procedures and background see Service Stop. Alterations to the service binary path or the service startup type changed to disabled may be suspicious. Monitor for changes made to Windows registry keys and/or values that may stop or disable services on a system to render those services unavailable to legitimate users. Monitor for newly executed processes that may stop or disable services on a system to render those services unavailable to legitimate users.

Log Sources
Data Component Name Channel
File Modification (DC0061) File None
Command Execution (DC0064) Command None
OS API Execution (DC0021) Process None
Process Termination (DC0033) Process None
Service Metadata (DC0041) Service None
Windows Registry Key Modification (DC0063) Windows Registry None
Process Creation (DC0032) Process None
Mutable Elements
Field Description